// FIREWALL AUDIT TOOL

Audit every firewall, from configuration, not guesswork.

SAMURAI is a self-hosted firewall audit tool that reads configuration state directly from the device: security policies, NAT, objects, and VPNs across Palo Alto, FortiGate, Cisco FMC/FTD and ASA, and Juniper SRX. It flags shadowed, redundant, and overly broad rules, computes what each rule really permits, and attributes every configuration change to the admin who made it, so a firewall configuration audit becomes an export instead of a fire drill.

Updated July 2026

What it audits

Rule hygiene findings

Shadowed, redundant, and overly broad rules flagged automatically across the whole rule base, the findings auditors look for first.

Effective access

What each rule actually permits end to end, with address and service objects resolved recursively and NAT applied, not just what the rule text says.

Change attribution

Every policy change detected from real device state and attributed to an admin, so who changed what and when has a documented answer.

Configuration audit trail

Snapshot history you can diff between any two points in time, catching changes that never wrote an audit-log entry.

Multi-vendor coverage

One audit across Palo Alto, FortiGate, Cisco FMC/FTD/ASA, and Juniper SRX, plus ACL visibility on routers, switches, and ACI fabrics.

Exportable evidence

Any table exports to CSV, XLSX, HTML, or PDF: the rule inventory, hygiene findings, and change timeline auditors ask for.

Configuration audit vs log-based reporting

A firewall audit answers what the rules are, whether they are clean, and who changed them. Those are configuration questions, not traffic questions, so log-based reporting tools answer the wrong half.

Data source

SAMURAI

Configuration state read from the device

Log-based reporting tools

Syslog and traffic logs

What the audit shows

SAMURAI

Rules, hygiene, effective access, and who changed what

Log-based reporting tools

What traffic passed or was denied

Change accountability

SAMURAI

Every change attributed to an admin

Log-based reporting tools

Not the focus of log reporting

Scope

SAMURAI

Firewalls plus routers, switches, ACI, ISE, and vCenter

Log-based reporting tools

Usually firewall logs only

Log analytics has its place for traffic forensics. But a configuration audit, what the rules are, whether they are clean, and who changed them, is what most firewall audits actually require, and that is what SAMURAI is built for. It does not run automated rule-recertification campaigns; it produces the analysis those workflows consume.

Frequently asked questions

What is a firewall audit tool?

A firewall audit tool reads firewall configuration and helps you verify it: what the rules permit, whether any are shadowed, redundant, or overly broad, and who changed them since the last review. SAMURAI does this from configuration state across Palo Alto, FortiGate, Cisco, and Juniper, and exports the evidence.

How do I audit firewall rules with it?

Register your firewalls; SAMURAI syncs their configuration and runs the Policy Analyzer over the rule base. You get shadowed, redundant, and overly broad findings, effective-access per rule, and a change timeline with admin attribution, all searchable and exportable. See the firewall audit checklist for the full workflow.

Is this a firewall log audit tool?

No, it audits configuration, not logs. It reads the rules, objects, and NAT from each device rather than parsing syslog, so you audit the policy itself and every change to it. For traffic-log forensics, pair it with a log platform.

Can it prove who changed a firewall rule?

Yes. Changes are detected from real device state and attributed to the admin (commit-correlated on PAN-OS, transaction-grouped on APIC, time-windowed on FortiOS/ISE/vCenter), so the audit trail names the author, not just the change.

Does it generate compliance reports?

It exports the rule inventory, hygiene findings, and change history to CSV, XLSX, HTML, or PDF, which is the evidence most audits need. It also runs 140+ CIS checks on Cisco IOS-XE, NX-OS, IOS-XR, and ASA. It does not produce framework-specific certification attestations.

Which firewalls can it audit?

Palo Alto (PAN-OS), FortiGate (FortiOS), Cisco FMC/FTD and ASA, and Juniper SRX (Junos OS), plus ACL visibility on Cisco routers, switches, and ACI fabrics.

Turn your next firewall audit into an export.

Request a demoExplore the platform